Data and AI Platform - Secure Data Lab
Secure Data Lab is a unified data, integration and AI accelerator providing a controlled environment to securely ingest, govern, analyse and operationalise data. It offers pre-configured architecture, tooling and governance controls to rapidly deliver analytics, reporting and AI use cases while remaining cloud-agnostic and compliant.
Features
- Cloud-agnostic data platform architecture
- Secure data ingestion from multiple sources
- Data integration, transformation, and orchestration
- Built-in data governance and access controls
- Analytics, reporting, and AI/ML enablement
- API-first design for integration with existing systems
- Secure Data Lab
Benefits
- Faster time-to-value for data and AI initiatives
- Reduced implementation risk through proven patterns
- Improved data quality, governance, and security
- Flexibility to operate across cloud environments
- Supports evidence-based decision making
- Compliant data analysis without risk of unauthorised access or leakage
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 8 9 9 0 0 5 4 4 7 5 7 0 2 8
Contact
Scout AI
David Smith
Telephone: 07949413262
Email: david.smith@joinscout.org
About your service
- Service categories
-
Application Development and Deployment
Data management
Database management systems
- Relational Database Management Systems
- Low-Code Database Management Systems
- Navigational Database Management Systems
- Fixed Record Database Management Systems
- Object-Oriented Database Management Systems
- Multivalue Database Management Systems
- Non-Schematic Database Management Systems
- Document-Oriented Database Systems
- Key-Accessible Database Systems
- Graph Database Management Systems
- In-Memory Shared Data Managers
- Data Lake Management Systems
Database administration and development
- Database Administration
- Database Replication
- Data Modelling
- Database Development and Optimization
Data integration and intelligence
- Data Ingestion and Transformation Software
- Dynamic Data Movement Software
- Data Quality Software
- Data Access Infrastructure Software
- Composite Data Framework Software
- Master Data Intelligence Software
- Metadata Management Software
- Data Archiving and Information LifD-Cycle Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Advanced analytics and AI model development
Data visualisation and dashboarding
Integration with third-party systems
Enhanced security and compliance controls
Training and enablement services - Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Requires an existing or provisioned cloud environment
Internet connectivity required for SaaS components
Performance dependent on underlying cloud infrastructure - System requirements
-
- Modern web browser
- Secure network connectivity
- Buyer-provided cloud tenancy where applicable
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Support queries are acknowledged within 1 business hour during standard support hours (09:00–17:00 UK time, Monday to Friday, excluding UK public holidays).
Initial responses are typically provided within:
4 business hours for standard queries
1 business hour for urgent or service-impacting issues (where an enhanced support package applies)
Weekend response times
At weekends and UK public holidays:
Support queries are monitored
Urgent, service-impacting issues receive a response within 4 hours
Non-urgent queries are responded to on the next business day
Response times and support hours can be extended by agreement as part of an enhanced support package. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Web chat functionality is designed and tested to meet accessibility requirements in line with WCAG 2.1 AA standards.
Testing activities include:
Keyboard-only navigation testing to ensure web chat can be accessed and operated without a mouse
Screen reader compatibility testing using commonly adopted assistive technologies (for example NVDA and VoiceOver)
Focus management and labelling checks to ensure messages, notifications, and controls are correctly announced
Colour contrast and text resizing checks to support users with visual impairments
Where third-party web chat components are used, the supplier relies on the vendor’s published accessibility conformance statements and undertakes internal validation as part of integration testing.
Accessibility feedback from users is reviewed and used to inform continuous improvement. Any identified accessibility issues are prioritised and addressed through the standard change and defect management process. - Onsite support
- Yes, at extra cost
- Support levels
-
The service is supported through tiered support levels aligned to buyer needs.
Standard Support (included)
Email and ticket-based support.
Support hours are 09:00–17:00 UK time, Monday to Friday, excluding UK public holidays.
Initial response is within 4 business hours for service-impacting incidents and 1 business day for non-urgent queries.
Access to documentation and knowledge base is provided.
The cost is included in the service price.
A dedicated technical account manager is not provided.
Enhanced Support (optional)
Email, ticketing, and phone support are provided.
Extended support hours include out-of-hours and weekend coverage.
Incidents are prioritised.
Initial response is within 1 hour for critical incidents.
An additional charge applies, either as a fixed annual fee or a percentage of the service subscription.
Access to a dedicated Technical Account Manager or Cloud Support Engineer is included.
Premium Support (optional)
Support is available 24×7×365.
Proactive monitoring and incident escalation are provided.
Initial response is within 30 minutes for critical incidents.
Pricing is quoted on request.
A named Technical Account Manager and Cloud Support Engineer are provided.
Support levels and pricing are agreed at contract award and may be varied by mutual agreement. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding begins with an initiation phase to confirm use cases, security requirements, deployment model, and success criteria. The supplier then configures the service environment, access controls, and integrations in line with buyer requirements.
Users are supported through a combination of guided setup, training, and documentation. Online training sessions are provided to introduce the service, core features, and common workflows. Role-based training can be tailored for technical users, administrators, and business users. Onsite training can be provided as an optional, chargeable service where required.
Comprehensive user documentation is provided, including setup guides, user manuals, and operational runbooks. Documentation is available online and kept up to date throughout the contract.
During early use, the supplier provides hypercare support to resolve issues, answer questions, and ensure users are able to operate the service confidently. Ongoing support and refresher training can be provided as part of enhanced support packages. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
All customer data is stored and processed within the buyer’s own cloud or hosting environment, not in a shared supplier-managed data store.
As a result, no bulk data extraction is required at contract end. Buyers retain full access to their data, schemas, models, and configurations within their environment and can continue to use, migrate, or archive the data independently.
Where any service metadata, configurations, or operational artefacts are managed by the supplier, these can be exported by the buyer or provided by the supplier in standard, open formats on request.
At contract termination, the supplier supports an orderly offboarding process that includes removal of supplier access, confirmation of access revocation, and written assurance that no buyer data is retained by the supplier outside the buyer’s environment. - End-of-contract process
-
Describe what happens at the end of the contract
At the end of the contract, the service enters a managed offboarding phase. As customer data is hosted within the buyer’s own environment, the buyer retains full access to all data, configurations, and outputs without interruption.
The supplier removes all supplier-managed access to the service and associated tools, confirms access revocation, and provides written assurance that no buyer data is retained outside the buyer’s environment. Any supplier-managed service components are decommissioned in line with agreed security and change processes.
Support is provided to ensure a smooth transition, including handover of documentation and confirmation of contract closure.
Describe what’s included in the price of the contract and what’s an additional cost
Included in the contract price
Standard offboarding activities, including access removal, confirmation of data retention arrangements, and provision of existing documentation, are included. Ongoing access to data within the buyer’s environment does not incur additional cost.
Additional costs
Optional services such as extended transition support, additional documentation, bespoke data exports, migration to alternative platforms, or continued support beyond the contract end are chargeable and agreed separately. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The service is designed to be configurable to support a wide range of use cases, from basic reporting and analytics to real-time data processing, secure environments, and scaled AI/ML workloads.
What can be customised
Data ingestion patterns, integration connectors, data models, and transformation logic can be configured to support batch, near real-time, or streaming data.
Analytics, dashboards, and AI/ML pipelines can be enabled or disabled based on use case.
Security controls, data access policies, network isolation, and encryption settings can be configured to meet organisational and regulatory requirements.
Infrastructure scaling, performance, and cost controls can be adjusted to match workload demands.
How users can customise
Customisation is carried out through configuration, policy settings, and APIs rather than source code changes.
Pre-defined templates and reference architectures are provided to accelerate setup for common use cases.
Who can customise
Authorised buyer administrators can configure the service within agreed permissions.
The supplier provides support, guidance, and optional professional services for more complex configurations.
Scaling
- Independence of resources
-
The service is designed so that each buyer operates within a logically and operationally isolated environment.
Where the service is deployed into a buyer’s own cloud environment, compute, storage, and networking resources are dedicated to that buyer and are not shared. This ensures that demand from other users does not affect performance, availability, or security.
For any shared service components, isolation is enforced through tenant separation, role-based access controls, and resource quotas. Capacity management and auto-scaling are used to ensure workloads scale independently based on demand.
The supplier monitors resource utilisation and performance and applies scaling and capacity controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides usage and operational metrics to help buyers understand how the platform is being used and to support service management and optimisation.
Metrics available include service availability and uptime, performance and response times, data ingestion and processing volumes, and utilisation of platform components such as analytics, integration, and AI/ML services.
Security and operational metrics are also available, including access activity, authentication events, and error rates, subject to buyer permissions and configuration.
Where the service is deployed into the buyer’s own cloud environment, metrics are available through native cloud monitoring tools and dashboards. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
All customer data is stored and processed within the buyer’s own cloud or hosting environment.
Users export their data directly from their environment using native platform tools, standard database access, and APIs. This includes self-service export of datasets, analytics outputs, and AI/ML artefacts without reliance on the supplier.
Where supplier-managed components generate configuration or operational metadata, this can be exported by authorised users or provided by the supplier on request using standard, open formats.
The supplier provides guidance and documentation to support data export and, where required, optional assistance as part of enhanced support or professional services. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
The service is designed to support high availability through resilient, cloud-based architecture.
Where the service is deployed into the buyer’s own cloud environment, overall availability depends on the underlying cloud platform selected by the buyer. The supplier configures the service in line with the cloud provider’s recommended availability and resilience patterns.
The supplier guarantees 99.9% availability for supplier-managed service components, measured monthly, excluding planned maintenance agreed in advance.
Availability targets, measurement methods, and exclusions are defined in the Service Level Agreement (SLA) provided with the service.
Service level agreements and refunds
If availability falls below the guaranteed level, buyers are eligible for service credits as set out in the SLA. Service credits are calculated as a percentage of the monthly service charge for the affected period and increase based on the severity and duration of the availability breach.
Service credits are applied to future invoices and represent the buyer’s sole remedy for failure to meet availability commitments. - Approach to resilience
-
The service is designed using resilient, cloud-native architecture to minimise the impact of component, service, or infrastructure failures.
Where deployed into a buyer’s cloud environment, resilience is achieved through the use of redundant compute, storage, and networking components, distributed across multiple availability zones within a region. The service supports automated scaling, health checks, and failover to maintain availability during periods of increased demand or partial failure.
Data resilience is provided through regular backups, replication, and recovery mechanisms aligned to buyer requirements and underlying cloud platform capabilities.
Datacentre resilience is provided by the third-party cloud service providers selected by the buyer. These datacentres are designed for high availability and include redundant power, cooling, network connectivity, and physical security controls. Datacentres are independently certified against recognised standards such as ISO/IEC 27001 and equivalent frameworks.
The supplier works within the shared responsibility model to ensure service configuration aligns with public sector resilience requirements. Further architectural and resilience details can be provided to buyers on request. - Outage reporting
-
Service outages and significant incidents are reported through multiple communication channels to ensure buyers are informed promptly.
Where applicable, a service status dashboard is made available to provide up-to-date information on service availability, incidents, and planned maintenance. This may include the use of the underlying cloud provider’s public status dashboard for infrastructure-related incidents.
Email notifications are used to alert nominated buyer contacts of service-impacting incidents, updates, and resolution status.
An API or machine-readable feed can be provided where supported, enabling buyers to integrate outage and status information into their own monitoring and service management tools.
Incident communications follow a defined process, including initial notification, regular updates during the incident, and a post-incident summary where appropriate.
The exact reporting mechanisms and notification channels are agreed with the buyer and documented as part of the service definition and support arrangements.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted to authorised users only and controlled through role-based access controls.
Administrative and management access is granted on the principle of least privilege and is limited to named, approved personnel. Strong authentication mechanisms are used, including multi-factor authentication where supported.
Support channels such as ticketing systems and collaboration tools are restricted to authenticated users and scoped to specific buyer accounts. Access is reviewed regularly and revoked promptly when no longer required.
All administrative access and support activity is logged and monitored to support audit and security oversight. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
The supplier operates a formal information security management framework aligned to recognised industry standards and UK public sector best practice.
Information security policies cover areas including access control, data protection, incident management, vulnerability management, change management, asset management, and business continuity. Policies are documented, approved, and reviewed on a regular basis.
Overall accountability for information security sits with a named board-level executive. Day-to-day responsibility is delegated to senior operational and technical leads who oversee implementation and compliance.
Policies are enforced through defined processes, technical controls, and role-based access restrictions. Compliance is supported by staff training, mandatory security awareness activities, and onboarding checks.
Adherence to policies is monitored through logging, audit, and regular internal reviews. Any security incidents or policy breaches are managed through a formal incident management process, with escalation, reporting, and corrective actions tracked to closure.
Where the service is deployed within third-party cloud environments, the supplier operates within the shared responsibility model and ensures policies align with the cloud provider’s security controls and certifications. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
The service operates under a controlled configuration and change management process aligned to recognised industry best practice.
All service components are identified and tracked throughout their lifecycle using configuration records and version control. This includes infrastructure, components, configurations, and supporting documentation. Changes are logged, traceable, and auditable from request through implementation and retirement.
Proposed changes are assessed using a structured change process that considers operational, availability, and security impacts. Security assessment includes review of access controls, data handling, encryption, and risk to confidentiality, integrity, or availability.
Changes are approved by authorised personnel before implementation and are tested in non-production environments. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
The service operates a proactive vulnerability management process aligned to recognised industry best practice.
Potential threats to the service are assessed through regular vulnerability scanning, dependency reviews, and security assessments of infrastructure, platforms, and applications. Risks are evaluated based on severity, exploitability, and potential impact on confidentiality, integrity, and availability.
Patches and mitigations are prioritised according to risk. Critical and high-severity vulnerabilities are addressed as soon as practicable, with emergency changes deployed outside normal change windows where required.
Information about potential threats is obtained from multiple sources, including cloud provider security advisories, vendor notifications, trusted security mailing lists, vulnerability databases. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Protective monitoring is implemented through centralised logging, alerting, and automated monitoring of service components and access activity. Potential compromises are identified using security events, anomaly detection, and predefined alert thresholds.
When a potential compromise is detected, alerts are triaged immediately and handled through a formal incident management process, including investigation, containment, and remediation. Relevant buyer contacts are notified in line with agreed procedures.
Service-impacting or security incidents receive an initial response within 1 hour, with ongoing updates provided until resolution. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
The service operates a formal incident management process with predefined procedures for common operational and security events. Users report incidents via email, ticketing, or phone support, depending on their support level.
Incidents are logged, prioritised, and managed through defined escalation and resolution workflows. Buyers are kept informed through regular updates, and post-incident reports are provided for significant incidents, outlining root cause, impact, and corrective actions. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-